IP Library Granted Patent US 10,013,694
Granted Patent B1
US 10,013,694 · App. 14/144,007 · Granted Jul 3, 2018

Open data collection for threat intelligence posture assessment

Inventors: Shachar Israeli (Hod Hasharon, IL); Ereli Eran (Rechovot, IL); Alex Zaslavsky (Petah Tiqwa, IL); Marcelo Blatt (Modiin, IL)
Assignee: EMC IP Holding Company LLC
G06Q20/4016G06Q50/01
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,013,694
App. No.
14/144,007
Filed
Dec 30, 2013
Granted
Jul 3, 2018
Kind
B1
Art Unit
3697
USPC
705/44
Abstract

An improved technique involves inputting data in postings from social media or news websites into a risk engine. A posting extraction device continually observes postings aggregated in social media and news websites, such as Twitter, Facebook, CNN, and the like. The posting extraction device parses postings that contain specified keywords such as “credit card,” “account number,” and the like. The posting extraction device also parses these postings for metadata such as user identifiers, times, and locations. The posting extraction device then stores the parsed information in a transaction database that is accessed by an adaptive authentication engine for risk score assignment.

Claims (59)

1. A method of employing social media data to improve accuracy of risk-based authentication, the method comprising:

observing, on a continual basis by processing circuitry of a posting extraction device, postings aggregated in a social media forum, said observing including (i) sending, by the posting extraction device, social media access requests to the social media forum to access a set of postings on the social media forum and (ii) searching, by the posting extraction device, the set of postings to identify a user post of a poster, the user post containing any of a set of keywords, each of the set of keywords having a specified impact on a risk score;

extracting, by the posting extraction device, data from the observed postings, the data including posting data from the user post, the posting data including discontinuous event data that includes at least one of the set of keywords and a time when the user post was made; and

assigning, by a risk-based authentication server, risk scores to a set of electronic transactions based on the extracted data, the risk scores being indicative of a risk of fraud in the set of electronic transactions, wherein assigning the risk scores includes, for a particular risk score, (i) computing a first risk score component based on a previous electronic transaction, (ii) computing a second risk score component based on the discontinuous event data, and (iii) producing the particular risk score based on the first risk score component and the second risk score component,

wherein the method further comprises:

storing the posting data from the user post in a transaction database in connection with a user identifier of the poster and further in connection with transaction history information of the poster;

receiving, by the risk-based authentication server after the user post was made, a request to authenticate an electronic transaction, the request to authenticate specifying the user identifier of the poster and a time when the request to authenticate is made; and

in response to the risk-based authentication server determining (a) that the time when the user post was made is more recent than any prior electronic transaction associated with the user identifier in the transaction history information and (b) that the posting data from the user post contains at least one of the set of keywords, (i) assigning a high risk score to the electronic transaction and (ii) preventing the electronic transaction from going forward.

2. The method as in claim 1 , wherein each of the set of electronic transactions includes values of transaction parameters;

wherein each of the observed postings includes metadata, the metadata including values of posting parameters;

wherein the method further comprises:

extracting the metadata of the observed postings; and

storing the values of the posting parameters in the transaction database; and

wherein assigning the risk scores includes:

accessing the values of the posting parameters stored in the transaction database.

3. The method as in claim 2 , wherein the values of the posting parameters of the metadata of a posting include the user identifier; and

wherein storing the values of the posting parameters in the transaction database includes:

placing the values of the posting parameters in a location in the transaction database according to the user identifier.

4. The method as in claim 2 , wherein assigning the risk scores to the set of electronic transactions further includes:

performing a comparison operation on a value of a transaction parameter of an electronic transaction of the set of electronic transactions with a value of a posting parameter of the set of posting parameters of the extracted metadata, and

generating the particular risk score based on a result of the comparison operation.

5. The method as in claim 4 , wherein performing the comparison operation includes:

comparing the time when the user post was made with the time when the request to authenticate was made to produce a time difference, the particular risk score being based on the time difference.

6. The method as in claim 4 , wherein the values of the posting parameters of the metadata of a posting include a geolocation indicating a location where the posting was introduced into the social media forum;

wherein performing the comparison operation includes:

comparing the value of the geolocation of the posting with a geolocation at which an electronic transaction was initiated to produce a location difference, the particular risk score being based on the location difference.

7. The method as in claim 1 , further comprising:

performing sentiment analysis on the set of keywords, a result of the sentiment analysis being one of a negative sentiment and a positive sentiment, the negative sentiment indicating an environment in which the risk of fraud in the electronic transaction is high, the positive sentiment indicating an environment in which the risk of fraud in the electronic transaction is low; and

wherein assigning the risk scores includes:

generating the particular risk score based on the result of the sentiment analysis.

8. The method as in claim 1 , wherein computing the first risk score component includes:

obtaining previous values of a transaction factor associated with the user identifier;

obtaining a new value of the transaction factor from the request to authenticate the electronic transaction; and

producing, as the first risk score component, a number indicating a likelihood that the transaction factor would have the new value given that the transaction factor has had the previous values,

wherein each of the observed postings includes metadata, the metadata including values of posting parameters;

wherein computing the second risk score component includes:

extracting the metadata of the observed postings;

accessing the values of the posting parameters from the metadata; and

producing, as the second risk score component, a number indicating a likelihood that the electronic transaction is fraudulent based on the values of the posting parameters, and

wherein producing the particular risk score based on the first risk score component and the second risk score component includes forming a sum of the first risk score component and the second risk score component.

9. The method as in claim 1 , wherein the set of keywords includes a word or phrase associated with an occurrence of a discontinuous event which increases a risk of fraud and which cannot be detected based solely on post time and location.

10. A computer program product having a non-transitory, computer-readable storage medium that stores instructions which, when executed by a controller, cause the controller to carry out a method of employing social media data to improve accuracy of risk-based authentication, the method comprising:

observing, on a continual basis by processing circuitry of a posting extraction device, postings aggregated in a social media forum, said observing including (i) sending, by the posting extraction device, social media access requests to the social media forum to access a set of postings on the social media forum and (ii) searching, by the posting extraction device, the set of postings to identify a user post of a poster, the user post containing any of a set of keywords, each of the set of keywords having a specified impact on a risk score;

extracting, by the posting extraction device, data from the observed postings, the data including posting data from the user post, the posting data including discontinuous event data that includes at least one of the set of keywords and a time when the user post was made; and

assigning, by a risk-based authentication server, risk scores to a set of electronic transactions based on the extracted data, the risk scores being indicative of a risk of fraud in the set of electronic transactions, wherein assigning the risk scores includes, for a particular risk score, (i) computing a first risk score component based on a previous electronic transaction, (ii) computing a second risk score component based on the discontinuous event data, and (iii) producing the particular risk score based on the first risk score component and the second risk score component,

wherein the method further comprises:

storing the posting data from the user post in a transaction database in connection with a user identifier of the poster and further in connection with transaction history information of the poster;

receiving, by the risk-based authentication server after the user post was made, a request to authenticate an electronic transaction, the request to authenticate specifying the user identifier of the poster and a time when the request to authenticate is made; and

in response to the risk-based authentication server determining (a) that the time when the user post was made is more recent than any prior electronic transaction associated with the user identifier in the transaction history information and (b) that the posting data from the user post contains at least one of the set of keywords, (i) assigning a high risk score to the electronic transaction and (ii) preventing the electronic transaction from going forward.

11. The computer program product as in claim 10 , wherein each of the set of electronic transactions includes values of transaction parameters;

wherein each of the observed postings includes metadata, the metadata including values of posting parameters;

wherein the method further comprises:

extracting the metadata of the observed postings; and

storing the values of the posting parameters in the transaction database; and

wherein assigning the risk scores includes:

accessing the values of the posting parameters stored in the transaction database.

12. The computer program product as in claim 11 , wherein the values of the posting parameters of the metadata of a posting include the user identifier; and

wherein storing the values of the posting parameters in the transaction database includes:

placing the values of the posting parameters in a location in the transaction database according to the user identifier.

Assignments (10)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (045455/0001) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061753/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (040136/0001) Recorded Apr 26, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO ASAP SOFTWARE EXPRESS, INC.); DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC CORPORATION (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MAGINATICS LLC); EMC IP HOLDING COMPANY LLC (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO MOZY, INC.); SCALEIO LLC
Reel/Frame 061324/0001 →
RELEASE OF SECURITY INTEREST Recorded Nov 3, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL, L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; WYSE TECHNOLOGY L.L.C.
Reel/Frame 058216/0001 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 29, 2016
From: EMC CORPORATION
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 040203/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 040134/0001 →
SECURITY AGREEMENT Recorded Sep 21, 2016
From: ASAP SOFTWARE EXPRESS, INC.; AVENTAIL LLC; CREDANT TECHNOLOGIES, INC.; DELL USA L.P.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL SOFTWARE INC.; DELL SYSTEMS CORPORATION; EMC CORPORATION; EMC IP HOLDING COMPANY LLC; FORCE10 NETWORKS, INC.; MAGINATICS LLC; MOZY, INC.; SCALEIO LLC; SPANNING CLOUD APPS LLC; WYSE TECHNOLOGY L.L.C.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 040136/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2014
From: ISRAELI, SHACHAR; ERAN, ERELI; ZASLAVSKY, ALEX; BLATT, MARCELO
To: EMC CORPORATION
Reel/Frame 032119/0238 →
Cited By (4)
US 12,301,529 US 12,333,578 US 12,495,028 US 12,608,691